Getting to the Core of the Matter

Locksmith Ledger All-Star Jacob Turnbow provides an inside look at how the University of Texas Medical Branch stays secure

With lock cores (see page 10) as one of the areas of focus for this special product-focused issue, Locksmith Ledger caught up with Jacob Turnbow, who works in the locksmith shop at the University of Texas Medical Branch, Galveston, Texas. Turnbow, who was recognized in the August issue as a Locksmith Ledger All-Star, serves as the lead locksmith, out of two locksmiths, for the entire University of Texas Medical Branch (UTMB) enterprise, which supports a community of more than 3,000 students and approximately 13,000 employees. 

The UTMB network spans over multiple campuses in the Galveston and Houston, Texas metroplex, and encompasses four major campuses, seven hospitals, and more than 45 facilities totaling over 2 million square feet of highly regulated clinical, academic, research, and high-containment laboratories. Additionally, Turnbow has oversight of a maximum-security prison hospital, and numerous outpatient clinics. In this role, he is responsible for ensuring consistent key control and core standards and supporting critical infrastructure.
 
In the following interview, Turnbow talks about the UTMB-wide initiative to improve long-term accountability by implementing an enterprise-wide core audit system, as well as strides the security team there has made in instituting a training and standardization materials for their key control officer program where Turnbow regularly trains new key control officers on systems and processes for requesting badge access, re-cores, and new keys.

Locksmith Ledger: What is your role at UTMB with so many buildings, doors, locks and hardware to deal with?

Turnbow: Our department is small, so we focus mainly on the lock cores themselves, and we don't handle the hardware extensively. We mainly manage the individual cores, and we use the small format interchangeable cores here predominantly. And usually, we can pin those up here in the shop and then go out in the field and install them. If it's a hardware issue, we'll turn it over to the building maintenance team because there's only a couple of us here in the lock shop. With a large campus, it's hard to deal with all the doors and all the hardware with just two people. And then we have a separate team within our department that handles electronic access control – the card readers and stuff like that. 

LL: Can you talk about the re-core initiative you started and where you are with that effort?

Turnbow: That's an ongoing project as we're trying to do a complete re-core of the whole system, which is going to be a multi-year rollout that's going to require a lot of coordinating between departments.

While most of what we use are a small format interchangeable cores (SFIC), we have a couple of locations, which due to the nature and circumstances of how we acquired it over time, there are some other systems out there, including some large format interchangeable systems as well. We have Sargent cores in one of our locations, and Medeco in one of our locations, which we're trying to transition over to the new Medeco X4, and there are small format interchangeable cores that use those keys. 

We're trying, ahead of the planned overall re-core, to move as many of those over to SFIC as possible. So, one of the goals of the re-core is to bring all of the locations under one system. And the more of those that we transition ahead of time, the less it's going to cost when we do the overall transition, because of the fewer hardware we're going to have to change out when we do the transition. The goal is to get it all under one system, but, as you know things expand and change and don't always work as planned.

For the SFIC, we're trying to move to the Cormax Plus with the new patent, as they're one of the newer patents out there. We're trying to future proof it to some extent. Obviously, over time, the standard for an industry for a keying system is usually 7 to 10 years. The assumption is after about that long; the system is probably compromised. And so, there's only so much future proofing that you can do, but with the longer patent, the more future proofing we can do. So that's one of the reasons why we want to do the audit report is we want to get something that's still protected by a patent, yet still a little bit more secure. 

LL: Can you talk some more about the core auditing process and what is involved for such a large enterprise?

Turnbow: We are catching up with the audit, which entails going through the buildings, so we're literally going door by door, pulling out the core, seeing what's stamped on the core, and then we go back and check our records. We're having to check our records, make sure that what our records say is in the door is what's actually in the door, so that we can be confident when we look up in our system. 

Occasionally, somebody will request a key, and we'll cut the key and it doesn't work, so we'll have to go out there and check the doors. And we're trying to catch stuff like that ahead of time so that it's not an inconvenience to the end user. If they have to return a key and get a new one after running into an issue like that, then it's a huge inconvenience, especially when they've got all their other workload to do and then they're dealing with keys. The point of that is catch those issues before it gets to the end user. 

With such a big enterprise, we do realize that as soon as we finish the audit process, though, we're going to have to restart it, as it is a continuing process.

LL: How do you manage the keys themselves? Who oversees the Master Keying system?

Turnbow: We're working with BEST for the master key system, and they work with our vendor who is the one that's actually assembling the master key system with us. And we're registering those codes with BEST through that vendor. And that way, if the grocery store across the street also has BEST, they're not going to have the same keyway as us, and they're not going to have the same key cuts as us. So, they're not going to accidentally end up with a ghost key that works on our campus, for example.

LL: Is this where the Key Control Officer program comes into play?

Turnbow: Yes. Here in the lock shop, we get the work orders that come in. And we have what we call key control officers around our campus. Each department has their key control officers and they're the people that are authorized to request the keys that that department controls. If anybody needs a key, they'll go to their key control officer and make the request, and the key control officer will be the one that will submit the work order, and we'll open it here in the lock shop. We'll cut the key and fill out the paperwork and then we'll turn it over to the badge office, because that's the customer-facing office on our side. 

We'll prepare the key and then we'll turn it over and they're the ones that distribute it, and the person who requests it will actually go to our badge office to sign out the key. So, we'll write it out on our records who's getting it, where it's going, and then they go to the badge office to sign for it.

LL: Please talk more about the challenge of managing all those different keys. 

Turnbow: Yes, when you've got a small facility, it's easy to say, if you need a key, send me an email. But you know, when you start getting into thousands of people, e-mail isn't going to cut it. You need some kind of work order system, and you need people that are designated that can authorize certain key distributions. And you can't keep track of all of that within one little lock shop, such as who's in what department and who's allowed to access which office or which labs are having special access and all that stuff. 

We can't keep track of that with just the two of us here in our little shop, so we need the coordination within the departments of the university. Somebody within that department knows what's going on and can say this person's allowed to have this key and this person's not. And those people not only have the authority to request the key, but they also have the authority to go to somebody and say, “hey, you don't need this key anymore, please turn it in.”

LL: Sounds like there must be a ton of ongoing training for the key control officers?

Turnbow: Yes, because the key control officers retire, they move to a different department, or job, so we're regularly having to do training. I train probably 10 to 15 key control officers a month, give or take. Some months more, some months less, but just whenever they're taking over for their department, I do a Teams call with them and I walk them through the process and standards. This is how you submit the work order. This is how the system works. This is where you go to get the information you need or for whatever you're looking for. That's the type of thing that that training program is for.

LL: How about in terms of overall compliance with key control policies across the organization? Is that part of the whole standardization process that you've been working on?

Turnbow: We do have specific key policies and a badge policy, and those were already in place before we started the re-core initiative. And over time there are exceptions made periodically. And so, you’ve got to keep track of it with the departments, especially if we've made any special exceptions or anything that goes as far as policies. 

For the most part, this re-core is offering an opportunity to not just audit the locks, but audit the individual departments, making sure that they're following policy. You know how it is when somebody retires: are they going to turn in their key or they are going to pass it to their buddy who needs the key, you know? And while the key control officers are supposed to be helping us monitor that with as many departments as we have and as many people as we have, there's no way you can catch all of them. 

This record is definitely going to be an opportunity to reset to 0 on that and make sure we know who has access to what again and make sure that there's no floating phantom keys out there that were reported lost that they didn't actually go lost, they just passed on – that type of thing. Unfortunately, a security system is only as good as the people who enforce it. So over time, you’ve got to reset to 0 and go back to the beginning at some point.

About the Author

Paul Ragusa

Senior Editor

Paul Ragusa is senior editor for Locksmith Ledger. He has worked as an editor in the security industry for nearly 10 years. He can be reached at [email protected].

Sign up for our eNewsletters
Get the latest news and updates